We are seeking a talented individual to join our GIS team at MMC Tech. This role will be based in Pune. This is a hybrid role that has a requirement of working at least three days a week in the office.
Senior Manager – IT Risk Management
The Global Information Security (GIS) team at Marsh is seeking a highly skilled and collaborativeSenior IT Specialistto serve as a trusted subject matter expert intechnical risk assessments, SaaS risk reviews, and third party risk management. In this role, you will lead complex evaluations of vendor and technology risk, challenge assumptions, and help shape risk decisions that support Marsh’s security, resilience, and business objectives. You will partner across security, engineering, infrastructure, procurement, privacy, and business teams to assess risk exposure, recommend practical controls, and strengthen governance across critical third party and SaaS relationships.
This is a hybrid role requiring three days per week in the office and two days per week remote.
WHAT YOU CAN EXPECT:
- A fast-paced environment with a strong culture and supportive leadership.
- The opportunity to influence high-impact technology and third party risk decisions.
- A role that combines deep independent ownership with broad cross-functional collaboration.
- Exposure to complex, strategic vendor and SaaS relationships across the enterprise.
WE WILL COUNT ON YOU TO:
- Lead advanced technical risk assessments across infrastructure, applications, cloud services, SaaS solutions, and supporting platforms.
- Serve as the primary reviewer for complex SaaS and third party environments, with emphasis on architecture, security design, resilience, and control maturity.
- Evaluate vendor-provided documentation, evidence, control narratives, and security attestations to identify gaps, exposures, and residual risk.
- Assess technical configurations, integration patterns, identity and access controls, data handling practices, encryption, logging, monitoring, and recovery capabilities.
- Review system architecture diagrams, application flows, and technical documentation to evaluate exposure and control effectiveness.
- Partner with security, engineering, infrastructure, procurement, privacy, and business stakeholders to translate technical findings into clear, actionable recommendations.
- Support and advance third party risk management activities, including vendor due diligence, issue tracking, remediation follow-up, exception handling, and stakeholder communication.
- Develop and maintain risk metrics, dashboards, and reporting materials that provide leadership visibility into key risks, trends, and remediation progress.
- Contribute to the enhancement and standardization of risk workflows, evidence collection, review criteria, and assessment methodologies.
- Help define and maintain guidance, standards, and playbooks for technical and SaaS risk assessments.
- Identify and escalate material risks, control gaps, and unresolved issues with sound judgment and appropriate urgency.
- Work independently on complex assessments while serving as a trusted resource to peers, leaders, and business partners.
- Support continuous improvement of the third party and SaaS risk program through process refinement, automation, and control maturity enhancements.
WHAT YOU NEED TO HAVE:
- Significant experience in technical risk assessments, cybersecurity, IT risk, third party risk, or a closely related technical discipline.
- Deep hands-on experience reviewing SaaS applications, vendor documentation, architecture, control evidence, and technical security configurations.
- Strong understanding of third party risk management concepts, vendor review processes, and control evaluation practices.
- Ability to assess complex technical information, identify material gaps, and provide clear, risk-based recommendations.
- Strong understanding of security controls, system architectures, cloud services, and modern application environments.
- Proven ability to partner effectively with technical and non-technical stakeholders in a large, complex, or regulated environment.
- Excellent communication skills, with the ability to influence decisions and present findings clearly to different audiences.
- Strong analytical thinking, sound judgment, and high attention to detail.
- Demonstrated ability to manage multiple complex assessments and priorities independently.
- Familiarity with remediation tracking, reporting, governance, and process improvement practices.
- Comfort evaluating risk in SaaS, cloud, infrastructure, and integrated third party environments.
WHAT MAKES YOU STAND OUT?
- Extensive experience leading technical risk assessments or SaaS reviews in an enterprise environment.
- Strong expertise in third party risk management, vendor due diligence, and control review activities.
- Proven ability to evaluate complex SaaS and third party environments and translate technical findings into business risk implications.
- Experience shaping or improving third party risk standards, assessment methodologies, or governance practices.
- Familiarity with cloud-native, infrastructure, and modern application architectures.
- Experience supporting remediation tracking, executive reporting, or risk documentation at scale.
- Demonstrated ability to influence stakeholders, drive alignment, and move complex issues forward independently.
- A proactive, strategic mindset with a strong interest in technology risk and third party oversight.
WHY JOIN OUR TEAM?
- We help you be your best through professional development opportunities, interesting work, and supportive leaders.
- We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and make an impact for colleagues, clients, and communities.
- Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to support your well-being.
Marsh McLennan (NYSE: MMC) is the world’s leading professional services firm in the areas of risk, strategy and people. The Company’s more than 85,000 colleagues advise clients in over 130 countries. With annual revenue of $23 billion, Marsh McLennan helps clients navigate an increasingly dynamic and complex environment through four market-leading businesses. Marsh provides data-driven risk advisory services and insurance solutions to commercial and consumer clients. Guy Carpenter develops advanced risk, reinsurance and capital strategies that help clients grow profitably and pursue emerging opportunities. Mercer delivers advice and technology-driven solutions that help organizations redefine the world of work, reshape retirement and investment outcomes, and unlock health and well being for a changing workforce. Oliver Wyman serves as a critical strategic, economic and brand advisor to private sector and governmental clients. For more information, visit marshmclennan.com, or follow us on LinkedIn and X.
Marsh McLennan is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people regardless of their sex/gender, marital or parental status, ethnic origin, nationality, age, background, disability, sexual orientation, caste, gender identity or any other characteristic protected by applicable law.
Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.
Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit corporate.marsh.com, or follow us on LinkedIn and X.Marsh is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, caste, disability, ethnic origin, family duties, gender orientation or expression, gender reassignment, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.Skills Required
- Significant experience in technical risk assessments, cybersecurity, IT risk, or third party risk
- Hands-on experience reviewing SaaS applications, vendor documentation, architecture, control evidence, and technical security configurations
- Strong understanding of third party risk management concepts, vendor review processes, and control evaluation practices
- Ability to assess complex technical information, identify material gaps, and provide clear, risk-based recommendations
- Strong understanding of security controls, system architectures, cloud services, and modern application environments
- Proven ability to partner effectively with technical and non-technical stakeholders in large or regulated environments
- Excellent communication skills with ability to influence decisions and present findings to different audiences
- Strong analytical thinking, sound judgment, and high attention to detail
- Demonstrated ability to manage multiple complex assessments and priorities independently
- Familiarity with remediation tracking, reporting, governance, and process improvement practices
- Experience shaping or improving third party risk standards, assessment methodologies, or governance practices
- Familiarity with cloud-native, infrastructure, and modern application architectures
- Experience supporting remediation tracking, executive reporting, or risk documentation at scale
Marsh McLennan Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Marsh McLennan and has not been reviewed or approved by Marsh McLennan.
-
Leave & Time Off Breadth — Leave offerings are described as generous, including sizable PTO, paid holidays, paid sick days, and additional time off such as paid volunteer time and “Summer days.” These time-off benefits are portrayed as a standout part of the overall rewards package.
-
Healthcare Strength — Healthcare coverage is characterized as comprehensive, spanning medical, dental, and vision options, with additional supports like disability and life insurance and access to mental health resources and an EAP. The breadth of plan options is positioned as a core strength of the benefits package.
-
Retirement Support — Retirement benefits are framed as solid, with 401(k) programs and employer matching frequently highlighted alongside other financial programs. Stock purchase options are also referenced as an additional wealth-building component of the total rewards mix.
Marsh McLennan Insights
What We Do
Marsh McLennan (NYSE: MMC) brings together nearly 78,000 experts in risk, strategy, and people across Marsh, Guy Carpenter, Mercer, and Oliver Wyman, serving clients in over 130 countries. Marsh enables enterprise worldwide by helping clients manage risks, transforming uncertainty into opportunity. Guy Carpenter helps clients grow profitably with reinsurance broking expertise, advisory services, and advanced analytics. Mercer helps organizations advance the health, wealth, and careers of their most vital asset — their people. Oliver Wyman’s expertise in strategy, operations, risk, and organization transformation changes what is possible for our clients, their industries, and society. Together, we combine a unique range of capabilities to help our clients solve problems, seize opportunities, and build lasting success in increasingly complex operating environments.







